{"repo":"smithy-security/smithy","free":true,"listed":false,"github":"https://github.com/smithy-security/smithy","clone":"git clone https://github.com/smithy-security/smithy.git","description":"The security workflow engine!","language":"Go","stars":140,"topics":["application-security","automation","cloud-security","devsecops","product-security","sdlc"],"license":"Apache-2.0","category":"workflow-automation","readme_excerpt":"Smithy Smithy: The AppSec Workflow Engine Smithy is a framework for building, automating, and standardizing security workflows, without drowning in dashboards or duct, taped scripts. Why Smithy? Security teams today juggle dozens of tools. Each is great at one thing, but none built to work together. Smithy solves this by letting you: Define workflows as code Integrate any tool with a simple SDK Normalize outputs into OCSF for consistent reporting Automate triaging, reporting or remedial actions with reusable, testable components Validate security controls for DevSecOps and GRC programs Use or contribute open workflows built by the community Whether you're managing cloud gremlins, AppSec scanners, compliance checks or evidence gathering, Smithy helps teams automate what matters— without building brittle glue code , because your bash scripts hate you. What It Looks Like Quickstart Prerequisites Go Docker Install Smithy with go install github.com/smithy-security/smithy/smithyctl@latest Execute a workflow Create the following files with the following contents: Then run the following command to run your workflow Check the findings in the logs. Stay in the Loop We’re building Smithy in the open and we’d love to keep you updated. Subscribe to the Smithy newsletter for: New workflow and component drops Release announcements Upcoming talks and workshops (BSides, DEFCON, OWASP, etc.) Tips on building smarter security workflows Sign up here it’s low-volume, high-signal. Developing and p","default_branch":null,"files":null,"tree":[],"storefront":"/r/smithy-security","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/smithy-security/smithy/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}